STIGhubSTIGhub
STIGsRMF ControlsCompare
STIGhub— A free STIG search and compliance tool·STIGs updated 3 days ago
Powered by Pylon·Privacy·Terms·© 2026 Beacon Cloud Solutions, Inc.
← CM-9 — Configuration Management Plan

CCI-001795

Definition

Implement a configuration management plan for the system that establishes a process for managing the configuration of the configuration items.

Parent Control

CM-9Configuration Management PlanConfiguration Management

Linked STIG Checks (4)

V-222630CAT IIThe Configuration Management (CM) repository must be properly patched and STIG compliant.Application Security and Development Security Technical Implementation GuideV-222631CAT IIAccess privileges to the Configuration Management (CM) repository must be reviewed every three months.Application Security and Development Security Technical Implementation GuideV-222632CAT IIA Software Configuration Management (SCM) plan describing the configuration control and change management process of application objects developed by the organization and the roles and responsibilities of the organization must be created and maintained.Application Security and Development Security Technical Implementation GuideV-222633CAT IIA Configuration Control Board (CCB) that meets at least every release cycle, for managing the Configuration Management (CM) process must be established.Application Security and Development Security Technical Implementation Guide